![]() Microsoft Security Bulletin (MS00-068) Patch Available for
“OCX Attachment” Vulnerability
Originally posted: September 26, 2000
Frequently asked questions regarding this vulnerability and the patch
can be found at http://www.microsoft.com/technet/security/bulletin/fq00-068.asp
The vulnerability would not cause any lasting effects. The user could
resume normal operation by restarting the mail client and deleting the
affected mail. Although the affected OCX control is associated with
Windows Media Player, it poses no threat to it – the vulnerability could
only be used to attack e-mail clients.
Note: The vulnerability only occurs if both Windows Media Player
7 and an affected e-mail client (Outlook or Outlook Express) are installed
on the same machine. Machines that only fulfill one of these conditions
are not affected.
Note Additional security patches are available at the Microsoft
Download Center
Please see the following references for more information related to
this issue.
This is a fully supported patch. Information on contacting Microsoft
Product Support Services is available at http://support.microsoft.com/support/contact/default.asp.
Microsoft thanks
Luciano Martins of USSR Labs (www.ussrback.com) for reporting this
issue to us and working with us to protect customers.
THE INFORMATION PROVIDED IN THE MICROSOFT KNOWLEDGE BASE IS PROVIDED
"AS IS" WITHOUT WARRANTY OF ANY KIND. MICROSOFT DISCLAIMS ALL WARRANTIES,
EITHER EXPRESS OR IMPLIED, INCLUDING THE WARRANTIES OF MERCHANTABILITY AND
FITNESS FOR A PARTICULAR PURPOSE. IN NO EVENT SHALL MICROSOFT CORPORATION
OR ITS SUPPLIERS BE LIABLE FOR ANY DAMAGES WHATSOEVER INCLUDING DIRECT,
INDIRECT, INCIDENTAL, CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL
DAMAGES, EVEN IF MICROSOFT CORPORATION OR ITS SUPPLIERS HAVE BEEN ADVISED
OF THE POSSIBILITY OF SUCH DAMAGES. SOME STATES DO NOT ALLOW THE EXCLUSION
OR LIMITATION OF LIABILITY FOR CONSEQUENTIAL OR INCIDENTAL DAMAGES SO THE
FOREGOING LIMITATION MAY NOT APPLY.
Last Updated September 28, 2000 |